Beveiligingsadvies

CVE-2023-1381

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-04-10 14:14:39
Laatst bijgewerkt 2025-02-11 17:21:25
Toegewezen door WPScan
CVSS-score 8.8
Status PUBLISHED

Beschrijving

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.